You are viewing a plain text version of this content. The canonical link for it is here.
Posted to reviews@ambari.apache.org by Sangeeta Ravindran <sa...@gmail.com> on 2017/04/13 17:16:50 UTC
Review Request 58425: Remove Server attribute from the HTTP response
headers
-----------------------------------------------------------
This is an automatically generated e-mail. To reply, visit:
https://reviews.apache.org/r/58425/
-----------------------------------------------------------
Review request for Ambari, Di Li, Robert Levas, and Tim Thorpe.
Bugs: AMBARI-20650
https://issues.apache.org/jira/browse/AMBARI-20650
Repository: ambari
Description
-------
Currently the HTTP response header contains the Jetty version.
Server:Jetty(8.1.19.v20160209)
To follow best security practices, it would be good to avoid including this information in the response headers.
Diffs
-----
ambari-server/src/main/java/org/apache/ambari/server/controller/AmbariServer.java 4e7af0c
Diff: https://reviews.apache.org/r/58425/diff/1/
Testing
-------
Manual Testing. Verified that "Server" header is removed from the HTTP response headers.
Thanks,
Sangeeta Ravindran
Re: Review Request 58425: Remove Server attribute from the HTTP
response headers
Posted by Di Li <di...@ca.ibm.com>.
-----------------------------------------------------------
This is an automatically generated e-mail. To reply, visit:
https://reviews.apache.org/r/58425/#review171902
-----------------------------------------------------------
Ship it!
Ship It!
- Di Li
On April 13, 2017, 5:16 p.m., Sangeeta Ravindran wrote:
>
> -----------------------------------------------------------
> This is an automatically generated e-mail. To reply, visit:
> https://reviews.apache.org/r/58425/
> -----------------------------------------------------------
>
> (Updated April 13, 2017, 5:16 p.m.)
>
>
> Review request for Ambari, Di Li, Robert Levas, and Tim Thorpe.
>
>
> Bugs: AMBARI-20650
> https://issues.apache.org/jira/browse/AMBARI-20650
>
>
> Repository: ambari
>
>
> Description
> -------
>
> Currently the HTTP response header contains the Jetty version.
> Server:Jetty(8.1.19.v20160209)
> To follow best security practices, it would be good to avoid including this information in the response headers.
>
>
> Diffs
> -----
>
> ambari-server/src/main/java/org/apache/ambari/server/controller/AmbariServer.java 4e7af0c
>
>
> Diff: https://reviews.apache.org/r/58425/diff/1/
>
>
> Testing
> -------
>
> Manual Testing. Verified that "Server" header is removed from the HTTP response headers.
>
>
> Thanks,
>
> Sangeeta Ravindran
>
>
Re: Review Request 58425: Remove Server attribute from the HTTP
response headers
Posted by Tim Thorpe <tt...@ca.ibm.com>.
-----------------------------------------------------------
This is an automatically generated e-mail. To reply, visit:
https://reviews.apache.org/r/58425/#review171903
-----------------------------------------------------------
Ship it!
Ship It!
- Tim Thorpe
On April 13, 2017, 5:16 p.m., Sangeeta Ravindran wrote:
>
> -----------------------------------------------------------
> This is an automatically generated e-mail. To reply, visit:
> https://reviews.apache.org/r/58425/
> -----------------------------------------------------------
>
> (Updated April 13, 2017, 5:16 p.m.)
>
>
> Review request for Ambari, Di Li, Robert Levas, and Tim Thorpe.
>
>
> Bugs: AMBARI-20650
> https://issues.apache.org/jira/browse/AMBARI-20650
>
>
> Repository: ambari
>
>
> Description
> -------
>
> Currently the HTTP response header contains the Jetty version.
> Server:Jetty(8.1.19.v20160209)
> To follow best security practices, it would be good to avoid including this information in the response headers.
>
>
> Diffs
> -----
>
> ambari-server/src/main/java/org/apache/ambari/server/controller/AmbariServer.java 4e7af0c
>
>
> Diff: https://reviews.apache.org/r/58425/diff/1/
>
>
> Testing
> -------
>
> Manual Testing. Verified that "Server" header is removed from the HTTP response headers.
>
>
> Thanks,
>
> Sangeeta Ravindran
>
>
Re: Review Request 58425: Remove Server attribute from the HTTP
response headers
Posted by Robert Levas <rl...@hortonworks.com>.
-----------------------------------------------------------
This is an automatically generated e-mail. To reply, visit:
https://reviews.apache.org/r/58425/#review171914
-----------------------------------------------------------
Ship it!
Ship It!
- Robert Levas
On April 13, 2017, 1:16 p.m., Sangeeta Ravindran wrote:
>
> -----------------------------------------------------------
> This is an automatically generated e-mail. To reply, visit:
> https://reviews.apache.org/r/58425/
> -----------------------------------------------------------
>
> (Updated April 13, 2017, 1:16 p.m.)
>
>
> Review request for Ambari, Di Li, Robert Levas, and Tim Thorpe.
>
>
> Bugs: AMBARI-20650
> https://issues.apache.org/jira/browse/AMBARI-20650
>
>
> Repository: ambari
>
>
> Description
> -------
>
> Currently the HTTP response header contains the Jetty version.
> Server:Jetty(8.1.19.v20160209)
> To follow best security practices, it would be good to avoid including this information in the response headers.
>
>
> Diffs
> -----
>
> ambari-server/src/main/java/org/apache/ambari/server/controller/AmbariServer.java 4e7af0c
>
>
> Diff: https://reviews.apache.org/r/58425/diff/1/
>
>
> Testing
> -------
>
> Manual Testing. Verified that "Server" header is removed from the HTTP response headers.
>
>
> Thanks,
>
> Sangeeta Ravindran
>
>